2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45387 | CRITICAL | 9.8 | 0.7% | Nov 17, 2023 | In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModul... |
| CVE-2023-48078 | CRITICAL | 9.8 | 0.8% | Nov 17, 2023 | SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands ... |
| CVE-2023-6014 | CRITICAL | 9.8 | 1.2% | Nov 16, 2023 | An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment. |
| CVE-2023-6019 | CRITICAL | 9.8 | 74.6% | Nov 16, 2023 | A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system r... |
| CVE-2023-6018 | CRITICAL | 9.8 | 47.9% | Nov 16, 2023 | An attacker can overwrite any file on the server hosting MLflow without any authentication. |
| CVE-2023-6016 | CRITICAL | 9.8 | 30.6% | Nov 16, 2023 | An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import f... |
| CVE-2023-47674 | CRITICAL | 9.8 | 1.3% | Nov 16, 2023 | Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated a... |
| CVE-2023-47213 | CRITICAL | 9.8 | 1.1% | Nov 16, 2023 | First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obta... |
| CVE-2023-47003 | CRITICAL | 9.8 | 1.1% | Nov 16, 2023 | An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafte... |
| CVE-2023-48365 | CRITICAL | 9.9 | 24.7% | Nov 15, 2023 | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.... |
| CVE-2023-41442 | CRITICAL | 9.8 | 1.3% | Nov 15, 2023 | An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute... |
| CVE-2023-48224 | CRITICAL | 9.1 | 1.0% | Nov 15, 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ... |
| CVE-2023-5245 | CRITICAL | 9.8 | 1.2% | Nov 15, 2023 | FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the a... |
| CVE-2023-47445 | CRITICAL | 9.8 | 0.8% | Nov 15, 2023 | Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page. |
| CVE-2023-47678 | CRITICAL | 9.1 | 0.7% | Nov 15, 2023 | An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are n... |
| CVE-2023-47308 | CRITICAL | 9.8 | 0.7% | Nov 15, 2023 | In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design fo... |
| CVE-2023-43979 | CRITICAL | 9.8 | 0.7% | Nov 15, 2023 | ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogMo... |
| CVE-2023-39337 | CRITICAL | 9.1 | 1.9% | Nov 15, 2023 | A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled... |
| CVE-2023-39335 | CRITICAL | 9.8 | 2.3% | Nov 15, 2023 | A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated... |
| CVE-2023-45616 | CRITICAL | 9.8 | 2.1% | Nov 14, 2023 | There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated rem... |
| CVE-2023-45615 | CRITICAL | 9.8 | 2.1% | Nov 14, 2023 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code e... |
| CVE-2023-45614 | CRITICAL | 9.8 | 2.1% | Nov 14, 2023 | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code e... |
| CVE-2023-47130 | CRITICAL | 9.8 | 3.1% | Nov 14, 2023 | Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE)... |
| CVE-2023-36049 | CRITICAL | 9.8 | 12.5% | Nov 14, 2023 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability |
| CVE-2023-34060 | CRITICAL | 9.8 | 1.3% | Nov 14, 2023 | VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now